Data Processing Addendum
Effective · Scripteco Technologies Private Limited
On this page
This Data Processing Addendum ("DPA") forms part of the Organisation Terms between Scripteco Technologies Private Limited ("Processor", "Askofy") and the Customer ("Fiduciary"). It applies whenever Askofy processes personal data on the Customer's behalf. Terms such as "personal data", "processing", "Data Fiduciary", "Data Processor", "Data Principal" and "personal data breach" have the meaning given in the Digital Personal Data Protection Act, 2023 and its Rules ("DPDP law").
1. Scope
- Subject matter: providing the Askofy platform for awareness campaigns, quizzes and certificates.
- Duration: the term of the Organisation Terms, plus the deletion period in section 9.
- Data Principals: the Customer's employees, contractors, patients, visitors, students, caregivers and guests who take its campaigns, and its admins.
- Personal data: names, work or personal contact details, employee code, department, designation, location, occupation or stream, age group, gender, city, campaign answers, scores, certificate codes and activity dates.
- Purpose: delivering campaigns, scoring, certificates, reminders, dashboards and exports, as the Customer instructs.
2. Instructions
Askofy processes this data only on the Customer's documented instructions. These include the Organisation Terms, campaign settings and the Customer's actions in the dashboard. We will tell the Customer if we believe an instruction breaks DPDP law.
3. Askofy's own purposes
Askofy may also, as a Data Fiduciary in its own right:
- create anonymised and aggregated data that no longer identifies anyone, and use it for research and to improve campaigns, as the Research Data Policy sets out
- keep certificate verification records, and process data to secure the service and meet legal duties
- contact participants who separately opted in to optional updates
4. Confidentiality and staff
Only authorised staff who need access may process personal data, under a duty of confidentiality. Access to contact details is masked by default and every reveal or export is logged with a reason.
5. Security
Askofy keeps reasonable security safeguards, as required by DPDP law, including:
- encryption in transit and at rest
- row-level access control separating each organisation's data
- secure admin login (one-time email links or hashed passwords) and least-privilege access
- access logging, backups, and monitoring for unusual activity
See Security.
6. Sub-processors
The Customer authorises the following sub-processors:
- Supabase Inc.: database, authentication and storage
- Cloudflare Inc.: hosting, content delivery and protection
- Hostinger International Ltd.: email delivery
Askofy binds each sub-processor to data-protection terms at least as protective as this DPA, and remains responsible for them. We will give at least 15 days' notice, by email or on this page, before adding or replacing one. The Customer may object on reasonable data-protection grounds. If we cannot address the objection, the Customer may end the affected subscription and receive a pro-rata refund.
7. Helping the Customer
Askofy will:
- promptly pass on any request received directly from a Data Principal, and help the Customer respond to requests for access, correction, erasure, nomination and grievances, mainly through dashboard tools such as export and delete
- provide information the Customer reasonably needs to show it complies with DPDP law
8. Personal data breach
Askofy will notify the Customer without undue delay, and in any case within 24 hours of becoming aware of a personal data breach affecting Customer data. We will provide what we know, including:
- the nature and likely impact of the breach
- the data and people affected
- the steps taken or planned
We will update the Customer as we learn more, and cooperate with the Customer's notices to affected Data Principals and the Data Protection Board of India. Askofy will also report to CERT-In within the time it requires.
9. Deletion and return
- During the term, the Customer can export its data at any time.
- After the term ends, Askofy will delete or anonymise the Customer's personal data within 90 days, and backups will expire within a further 30 days.
- The exceptions are data Askofy must keep by law, and certificate verification records kept as the Certificate Policy says.
- On request, Askofy will confirm deletion in writing.
10. Transfers
Data may be processed outside India by the sub-processors listed above, but only in line with DPDP law and never to a country the Government of India restricts.
11. Audits
Once a year, or after a personal data breach, the Customer may ask for:
- a written description of our safeguards, and
- answers to a reasonable security questionnaire.
On-site audits need 30 days' notice, must be at the Customer's cost, and are subject to confidentiality and our providers' rules.
12. Liability and precedence
Liability under this DPA is subject to the limits in the Organisation Terms. If this DPA conflicts with the Organisation Terms on data protection, this DPA prevails.
Scripteco Technologies Private Limited · Mumbai, Maharashtra, India